I'm a Network & Systems Engineer / Teaching Lab Aid focused on cybersecurity, network observability, and AI infrastructure. I build SOC tooling, MCP servers, and agent workflows that run on real production gear, not toy demos. I write about it at solomonneas.dev/blog.
US based in Tampa, FL, near the beach.
- ๐ M.S. Cybersecurity Intelligence & Information Security at the University of South Florida.
- ๐ก๏ธ Building open-source SOC + threat intel tooling on bare-metal Proxmox.
- ๐ค Deep in multi-agent orchestration, MCP servers, and detection engineering.
- ๐ชข n8n enthusiast, wiring up self-hosted automation for intel pipelines, monitoring, and SOC ops.
- ๐งญ Currently exploring self-hosted AI stacks, network observability, and incident response automation.
- ๐ Writing regularly on my blog, Dev.to, Hashnode, CoderLegion, and X.
- ๐ฃ๏ธ Ask me about Proxmox migrations, network monitoring, MCP servers, OpenClaw, agent orchestration, and open-source SOC.
- โ๏ธ Big believer in open source, dogfooding everything, and writing it down so the next person doesn't have to figure it out.
- ๐จโ๐ง Father, retired chef of 17 years, OSS contributor, and beach lover when I'm not on a screen.
- ๐ซถ If my work helped you, buy me a coffee or tip on Ko-fi.
- ๐ซ Reach me at me@solomonneas.dev ยท LinkedIn ยท X
Some of the projects I've built or maintain:
OpenClaw & Dev Tools
- ๐ code-search-api - Local semantic code search with Ollama embeddings, SQLite, hybrid search, and LLM summaries.
- ๐ฆ solos-cookbook - Solomon's Guide to Cookin' with Gas: how one engineer runs a 24/7 multi-agent AI stack on bare metal. Opinionated. Dogfooded. Broken-and-fixed in production. Tested in service.
- ๐ usage-tracker - Token usage and cost analytics for OpenClaw sessions across models.
- ๐ prompt-library - Dual-mode prompt management with browse/copy UI and a REST API for sub-agents.
- ๐ content-guard - Policy-driven content scanning and publish checks.
Security & Threat Intelligence
- ๐ก๏ธ cyberbrief - AI threat intel briefings with BLUF reports, ATT&CK mapping, and IOC extraction.
- ๐ bro-hunter - Threat hunting for Zeek and Suricata logs with beaconing detection and MITRE mapping.
- ๐ฌ intel-workbench - Threat intel analysis with ACH matrices, evidence weighting, and STIX export.
- ๐ hotwash - SOC playbook parser with mermaid diagram generation and Wazuh alert ingestion.
- ๐๏ธ soc-stack - Full SOC architecture covering MCP servers, detection pipelines, and deployment playbooks.
MCP Servers
- ๐ง cortex-mcp - Observable analysis for IOCs, reports, and response actions.
- ๐ก๏ธ wazuh-mcp - SIEM access for agents, alerts, rules, and decoders.
- ๐ฌ misp-mcp - Threat intel search, IOC correlation, and STIX/Suricata/CSV export.
- ๐ thehive-mcp - Incident response workflows for cases, alerts, tasks, and observables.
- โ๏ธ mitre-mcp - MITRE ATT&CK technique mapping, threat group profiling, and detection gap analysis.
- ๐ zeek-mcp - Network monitoring access for connection, DNS, HTTP, and SSL logs.
- ๐ฆ suricata-mcp - IDS/IPS workflows for managing rules, querying alerts, and analyzing traffic.
- ๐ธ๏ธ maltego-mcp - Maltego graph authoring and OSINT lookups for whois, DNS, ASN, and crt.sh.
- โ๏ธ n8n-ops-mcp - Ops control for n8n workflows, validation, and execution lifecycle.
- ๐ฎ postiz-mcp - Postiz social scheduling control with full public-API coverage, env-gated writes, and a 30/hr rate-limit guard.
Network & Infrastructure
- ๐ญ watchtower - NOC dashboard with interactive topology, L2/L3 views, and LibreNMS/Proxmox integration.
- ๐ portgrid - Switch port visualization for LibreNMS with color-coded views and instant search.
- ๐ proxguard - Proxmox firewall rule visualization with conflict detection and rule simulation.
- ๐ง samba-ad-migration - Windows AD to Samba file share migration scripts for Proxmox.
Media Automation
- ๐บ media-cli - Single-file bash CLI for Sonarr, Radarr, Prowlarr, qBittorrent, Bazarr, Jellyseerr, and Tdarr.
- ๐ฌ jellyfin-mcp - Control Jellyfin from LLMs with playback sessions, library scans, user admin, and 20 MCP tools.
Currently Contributing To
- ๐ง vincentkoc/tokenjuice - Lean output compaction for terminal-heavy agent workflows.
- ๐ steipete/summarize - Fast summaries from URLs, files, and media. CLI + Chrome Side Panel + Firefox Sidebar with video slides, OCR, and transcript extraction.
- ๐ฌ steipete/gogcli - Google Suite CLI for Gmail, Calendar, Drive, and Contacts.
- ๐ฆ openclaw/plugin-inspector - Offline compatibility inspector for mocking OpenClaw and testing plugins.
- ๐ openclaw/acpx - Headless CLI client for stateful Agent Client Protocol (ACP) sessions.
- ๐ฌ steipete/discrawl - CLI for Discord with a SQLite backend.
- ๐ญ microsoft/playwright - Cross-browser automation and testing framework, including the Playwright MCP server for agents.
I'm always open to building, contributing, collaborating, and chatting. Feel free to reach out.
Infrastructure Migrations
- ๐ฐ How I Migrated 6 Servers from VMware to Proxmox and Saved $343K
- ๐ฅ๏ธ I Migrated Our Entire Infrastructure from Hyper-V to Proxmox
- ๐ฟ Replacing SCCM with FOG Project
SOC & Security Operations
- ๐ก๏ธ I'm a Lab Assistant. So I Built My Own SOC
- ๐งฉ I Built 7 MCP Servers for Security Tools. The Protocol Was the Easy Part.
Network Engineering
- ๐ก A Fiber Cut at 2 PM Taught Me Why I Needed to Build Watchtower
- ๐ 3 Days, 18 Hours: What I Learned at NDG's Proxmox Workshop
Agents & AI Infrastructure



